Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-16598

Опубликовано: 10 дек. 2020
Источник: redhat
CVSS3: 5.5

Описание

[REJECTED CVE] A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils, in debug_get_real_type, as demonstrated in objdump, that can cause a denial of service via a crafted file.

Отчет

The version of binutils shipped in Red Hat Developer Toolset 10 and Red Hat Enterprise Linux 8's GCC Toolset 10 is not affected by this flaw because it has already been patched. Also, please note that this CVE has been rejected Upstream and it is not considered as a security issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5binutilsOut of support scope
Red Hat Enterprise Linux 5binutils220Out of support scope
Red Hat Enterprise Linux 6binutilsOut of support scope
Red Hat Enterprise Linux 7binutilsOut of support scope
Red Hat Enterprise Linux 8binutilsFix deferred
Red Hat Enterprise Linux 8gcc-toolset-10-binutilsNot affected
Red Hat Enterprise Linux 8gcc-toolset-9-binutilsFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-476
https://bugzilla.redhat.com/show_bug.cgi?id=1906756binutils: Null Pointer Dereference in debug_get_real_type could result in DoS

5.5 Medium

CVSS3

Связанные уязвимости

ubuntu
около 5 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

nvd
около 5 лет назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

github
больше 3 лет назад

A Null Pointer Dereference vulnerability exists in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.34, in debug_get_real_type, as demonstrated in objdump, that can cause a denial of service via a crafted file.

suse-cvrf
больше 4 лет назад

Security update for binutils

suse-cvrf
больше 4 лет назад

Security update for binutils

5.5 Medium

CVSS3